Me: "All the so-called private messaging apps have inferior cryptography engineering and need to step up their game. It kind of sucks that Signal is the only game in town that has decent e2ee. We can do better. The community just has to have higher standards and stop settling for bad designs."
The NSA is handicapped by being a dual-mission agency. The same organisation is responsible for:
Making sure that the USA's signals are secure.
Making sure that no other country's signals are secure from the USA.
These are in obvious tension when the USA and everyone else are using the same off-the-shelf standards and implementations of those standards.
I'm generally happy that they now prioritise the former over the latter, if only because they now know that there is a good chance that any weakness that they put in will be exploited by the Chinese, but I'd be a lot more comfortable if they properly separated the two concerns.
I am still curious about Heartbleed because a lot of the US government was vulnerable and I know the NSA did some review of OpenSSL, so I don't know which of the following options was true:
They didn't bother to review a core piece of security-critical software that a lot of the government's security depended on (I have some evidence that it wasn't this one).
They did review it and missed a really important bug.
They did review it, found the bug, and made a staggeringly bad call about whether it was better to fix the bug or keep it as a thing to attack other people with.
None of these possibilities makes them look especially competent.
@drwho Orr is, apparently, generally positively regarded by my peers. Their email (but mostly the IETF thread that preceded it) just struck me the wrong way.
There are very intelligent and passionate engineers, cryptographers, and analysts that vehemently disagree with my conclusions about the Hybrid debate. That's okay!
But Bernstein summoned a mob of ill-informed people with messages designed to alarm them into action.
Every one of these agencies has a mission and a budget. To your or I, that budget might seem like "damn near infinite", but they still have constraints.
NSA has two missions. Everyone knows about SIGINT because of Snowden, but they also have a competing mission called COMINT.
You can, very loosely, map these two terms to "red team" and "blue team".
If NSA knew a top secret way to break ML-KEM and were fairly confident that no other country has thought of it, there is no way in hell the SIGINT people could get the COMINT people to agree on a plan to migrate the entire federal fucking government to use ML-KEM. It doesn't line up with their self-interest.
Like, I am NOT a fan of the NSA, in the same way that I'm not a fan of Meta, Palantir, and the data broker industry.
Surveillance is bad for society. Privacy is good for society. Using technology to undermine privacy and surveil people is a bad thing, actually. And while the official story is roughly that NSA only spies on other governments, and not innocent civilians, we have no way of knowing if that's true. And there's no way in hell I'll ever trust that.
So, like most cryptographers, I'm squarely in the "Fuck the NSA" camp. Just like I'm in the "Fuck the FSB" camp. And every other nation state's equivalent agency is on that list too.
But spy agencies aren't fucking magical. They can't violate information theory, physics, or causality.
They also aren't omniscient about mathematics, logic, or software vulnerabilities. If they were, they wouldn't have competition. And they can't wave a magic wand and get enthusiastic cooperation from international forums of cryptology experts. That's ridiculous.
@christopherkunz Yeah. Reasonable people can disagree on Pure PQ vs Hybrid PQ, but summoning unreasonable shit-stirrers into the thread is a huge waste of everyone's time and energy.
He/him. Gay/demi dhole (Cuon Alpinus) furry.Blogger, programmer, security engineer, cryptography nerd. 30+Too spicy for Twitter (banned with all the prominent journalists on 2022-12-16)I don't represent any company, individual, or community.